# Rippling: 22 point Door Gap
- Site: rippling.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/rippling-nbet7v
- Scanner version: 12
A network edge blocks five AI crawlers that robots.txt welcomes, and the API surface is undocumented, leaving agents unable to evaluate or integrate.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 73/100 |
| Agents | 51/100 |
| Composite | 62/100 |
| Door Gap | 22 points |
| Percentile | 48th |
The human score is the mean of the four human dimensions, the agent score the mean of the six agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The agent got through 7 of 15 requests, but could not ask whether the door opens for requests carrying the AI crawlers' names. It came up empty on 7 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- missing ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- missing find a comparison page worth citing
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **No developer documentation is linked from the homepage, in raw HTML or the rendered page, so integration starts with a search engine.** (programmatic_onboarding)
2. **The API documentation is empty and contains no credentials, endpoints, code samples, or authentication details, making programmatic integration impossible without a sales call.** (programmatic_onboarding)
3. **No comparison or alternatives page is published, so agents cannot see how Rippling compares to competitors when shortlisting vendors.** (machine_discoverability)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/rippling-nbet7v
## Files generated from this scan
- **Pricing as Offer structured data** at `pricing page`, 20 minutes, developer. Verify: The next scan reads Offer structured data with a price and currency on the pricing page, and the pricing check credits it.
- **Let verified assistants through** at `notes`, 1 hour, developer. Verify: The next scan opens the homepage and the key pages in a real browser and under the search crawler names, and every one is served.
- **A comparison page brief** at `/compare/rippling-vs-competitor`, 3 hours, no developer needed. Verify: The next scan finds a comparison page listed in the sitemap or linked from the homepage, and reads its text without JavaScript.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/rippling-nbet7v
## The agent door
- **machine_discoverability** 95/100. Rippling publishes a sitemap with 610 URLs, structured data on the homepage (Product, AggregateRating, Organization), and llms.txt. A real browser is served normally.
- **programmatic_onboarding** 10/100. The developer documentation at developer.rippling.com contains only 33 characters of text and shows no API credentials, endpoints, code samples, authentication documentation, or GraphQL support.
- **pricing_legibility** 85/100. Four prices are readable without JavaScript on the pricing page, all listed at $250. No tier is gated behind a sales contact or demo requirement. The pricing is legible and published, though the page does not specify what each tier.
- **agent_aware_instrumentation** 8/100. No MCP manifest is published at the three standard paths checked (/.well-known/mcp.json, /.well-known/mcp, /mcp.json). An agent cannot discover or invoke Rippling capabilities through the Model Context Protocol, the emerging standard for.
- **machine_fetchable_trust** 40/100. No security.txt is published at /.well-known/security.txt. The homepage responds to automated requests, but the absence of a security contact or vulnerability disclosure policy means an agent cannot verify the company's security posture or.
- **commercial_rails** 65/100. Prices are published in raw HTML on the pricing page without JavaScript. A self serve signup form is reachable from the homepage in 2 steps, with 3 required fields and no payment collection at signup.
## The human door
- **steps_to_first_value** 80/100. The primary call to action on the homepage leads to a signup form in 2 steps. The form collects email address and company details. No account system is required to view pricing or product information, so a visitor can evaluate the product.
- **required_fields** 65/100. The signup form contains 3 fields, all 3 required. Each field carries a validation rule (email format, text input constraints). The form does not ask for payment, phone number, or company verification at signup, keeping the barrier to.
- **verification_walls** 65/100. The signup page does not display any email verification, phone verification, or identity verification requirement. The form accepts input and carries validation rules, but no evidence of a verification step appears before access is.
- **error_recovery** 80/100. All 3 input fields carry validation constraints and descriptions. The form includes 1 live region for error messaging. No inline error containers were observed, but the validation rules are present and should catch common mistakes before.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
